ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 19 sources: “Ubuntu roundup (2026-09-16 to 2026-09-18): ten USNs fix 16 CVEs, including Rclone unauthenticated command execution and Arm kernel TLB race” — merged summary and timeline →

USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities

AI summary · glm-5.3-flash

Ubuntu fixes CVE-2025-27558, a Linux WiFi mesh flaw caused by an incorrect CVE-2020-24588 fix, letting physically proximate attackers inject packets, plus other kernel updates.

Ubuntu released USN-8715-2 for the Linux kernel on the AWS FIPS variant. Siebe Devroe, Heloise Gollier, and Mathy Vanhoef discovered CVE-2025-27558: the kernel's WiFi implementation mishandles aggregated frames in mesh networks due to an incorrect fix for CVE-2020-24588, allowing a physically proximate attacker to inject packets. The update also corrects flaws in x86, cryptographic API, InfiniBand, media, network, and NVMe drivers, and file systems.

  • Fixes CVE-2025-27558: WiFi mesh aggregated frame handling flaw enabling packet injection.
  • Root cause is an incorrect fix for CVE-2020-24588.
  • Discovered by Siebe Devroe, Heloise Gollier, and Mathy Vanhoef.
  • Targets Ubuntu's Linux kernel AWS FIPS variant (USN-8715-2).

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-24588
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the p

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.

NVD description · AI analysis pending
3.54% PoC
  • ieee ieee 802.11
  • ieee mac80211
  • ieee windows 10
  • +1 more
CVE-2025-27558
IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks.

IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.

NVD description · AI analysis pending
9.1<1%
Full article

Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - OCFS2…

This source does not provide full text. Read it at ubuntu.com.